Research Article

Group Signatures with Message-Dependent Opening: Formal Definitions and Constructions

Box 5

The Abe-Haralambiev-Ohkubo signature scheme, where denotes the message length (in group elements) of the scheme. The algorithm randomizes a pair under the constraint that the pairing is unchanged. The algorithm produces a set of pairs and which are uniformly random with the constraint that .
SigKg:
,
 For :
,
,
 Output
Sign:
, , ,
 Output
Verify:
 If
and then
Output
 Else
Output
Rand:
 If and then
Output
 Else
If then
Output
Else
If then
Output
Else
Output
Extend:
Output